Orbit Security Safe Harbor
Technical Architecture & Safe Harbor

RFC Passive Scan Disclaimer

Last Updated & Effective Date: September 26, 2026

Defensive Security & Good-Faith Safe Harbor

Orbit Security is engineered exclusively as a defensive, passive perimeter reconnaissance and attack surface hygiene tool. Our systems operate in accordance with the U.S. Department of Justice Revised Charging Policy under the Computer Fraud and Abuse Act (18 U.S.C. ยง 1030), which protects good-faith security research and defensive posture auditing designed to correct vulnerabilities before malicious adversaries exploit them.

1. Technical RFC Standards Compliance

All reconnaissance procedures executed by Orbit Security (including the client-side DNS-over-HTTPS scanner and the Orbit Recon engine) strictly query open, public standards without altering, injecting, or manipulating remote server states:

RFC 1035 / RFC 8482 ๐Ÿฑ
Domain Name System (DNS) query protocols for A, CNAME, and TXT routing records. (Checks for abandoned lockers).
RFC 7208 / RFC 7489 ๐Ÿฑ
Public Sender Policy Framework (SPF) & DMARC authentication policy verification. (The VIP guest list & bouncer).
RFC 8484 / RFC 6962 ๐Ÿฑ
DNS-over-HTTPS (DoH) encrypted queries and public Certificate Transparency log inspection (crt.sh).
RFC 9110 / RFC 8446 ๐Ÿฑ
Standard HTTP/1.1 & HTTP/2 GET requests inspecting public response headers and TLS deadbolts.

2. Explicit Prohibitions & Anti-Exploitation Guarantees

Orbit Security incorporates strict hardcoded architectural bounds to ensure it never crosses into unauthorized access or offensive exploitation:

  • No Payload Injection: We never transmit SQL injection, cross-site scripting (XSS), remote code execution (RCE), or binary payloads.
  • No Credential Stuffing or Brute-Forcing: We never attempt to crack passwords, bypass logins, or test dictionary credentials.
  • No Dangling Subdomain Registration: When a dangling CNAME record is identified (e.g. Unbounce, S3, GitHub Pages), Orbit Security never registers or claims the target asset. We flag the orphaned pointer so the legitimate domain owner can remove it.
  • No Data Exfiltration: Probes for sensitive file exposure (such as /.env or /.git/HEAD) stream a maximum of 256 KB to identify fingerprint needles. Orbit Security never logs, stores, or extracts proprietary database passwords, cryptographic keys, or customer records.
  • No Denial of Service (DoS): Queries are rate-limited, pooled, and throttled to prevent server degradation or bandwidth exhaustion.

3. Legal Precedent & Legal Alignment

Following the landmark U.S. Supreme Court decision in Van Buren v. United States (2021), accessing publicly available endpoints and information that does not require bypassing password-protected barriers or technological access controls does not constitute a violation of the Computer Fraud and Abuse Act. Orbit Security operates exclusively on the external, public perimeter.

4. Regulatory Standards & Compliance Alignment

Orbit Security's automated heuristics are explicitly mapped to recognized web security and email deliverability frameworks:

Google & Yahoo 2024 Sender Mandates

Automates mandatory verification of SPF alignment, DKIM signatures, and strict DMARC (p=quarantine or p=reject) to prevent bulk email rejection.

PCI-DSS v4.0 Requirement 6.4.3 & 11.6.1

Assists ecommerce agencies in confirming Content-Security-Policy (CSP) script authorization and HTTP header tampering shields across checkout perimeters.

OWASP Top 10 A05: Security Misconfiguration

Continuously tracks dangling DNS pointers to decommissioned cloud assets (AWS S3, Shopify, Unbounce) to eliminate hostile subdomain takeovers.

FTC Safeguards & Cyber Insurance Hygiene

Provides objective third-party monthly PDF audit documentation required by cyber insurance underwriters to substantiate proactive perimeter care.

5. Agency-Client Safe Harbor Contract Rider (Copy-Paste for Agency MSAs)

AGENCY SHIELD

Agencies subscribing to Orbit Security may incorporate the following standard provision into their client Master Services Agreements (MSAs), Web Care Plans, or Maintenance SOWs to establish clear contractual authority:

"Client authorizes Agency and its automated security telemetry partners (including Orbit Security) to conduct continuous, non-intrusive external perimeter reconnaissance, DNS authentication analysis (SPF/DKIM/DMARC), subdomain routing checks, and public HTTP header verification across Client's digital domains and staging properties. Client acknowledges that all surveillance is conducted passively or via standard RFC-compliant HTTP queries without payload execution or access-control bypasses, and serves solely to maintain attack surface hygiene."

6. Domain Exclusion & Opt-Out Request

If you are the verified administrative contact of a domain and wish to permanently block your domain from being queried by Orbit Security users or our automated sentinel fleet, you may request immediate inclusion in our global exclusion registry.

Email carsonmail009@gmail.com with the subject "Domain Exclusion Request" from an authorized domain address (e.g., security@yourdomain.com). Exclusions are processed and locked within 24 hours.